Enhanced Blocks – Page Builder Blocks for Gutenberg Security & Risk Analysis

wordpress.org/plugins/enhanced-blocks

Build responsive websites using the latest Gutenberg editor blocks. Enhanced Blocks is the first ever page builder for Gutenberg Editor with all the b …

100 active installs v1.4.1 PHP + WP 4.8+ Updated Sep 23, 2019
blockeditorgutenberg-blockspage-buildersite-builder
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 19, 2025
Safety Verdict

Is Enhanced Blocks – Page Builder Blocks for Gutenberg Safe to Use in 2026?

Use With Caution

Score 63/100

Enhanced Blocks – Page Builder Blocks for Gutenberg has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 19, 2025Updated 6yr ago
Risk Assessment

The "enhanced-blocks" plugin v1.4.1 presents a mixed security posture. While the static analysis indicates no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests, there are significant concerns. The plugin exposes two AJAX handlers, both of which completely lack authentication checks. This is a critical oversight that could allow unauthenticated users to trigger plugin functionality, potentially leading to unauthorized actions. The vulnerability history also shows a pattern of missing authorization, with a currently unpatched medium severity vulnerability. This historical trend reinforces the concerns raised by the static analysis regarding the lack of proper authorization checks.

Key Concerns

  • AJAX handlers without auth checks
  • Unpatched CVE present
  • Missing authorization in history
  • Low percentage of properly escaped output
Vulnerabilities
1

Enhanced Blocks – Page Builder Blocks for Gutenberg Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-50034medium · 4.3Missing Authorization

Enhanced Blocks &#8211; Page Builder Blocks for Gutenberg <= 1.4.1 - Missing Authorization

Jun 19, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Enhanced Blocks – Page Builder Blocks for Gutenberg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
22
41 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

65% escaped63 total outputs
Attack Surface
2 unprotected

Enhanced Blocks – Page Builder Blocks for Gutenberg Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_enhanced_get_saved_blockssrc\init.php:192
authwp_ajax_enhanced_delete_saved_blocksrc\init.php:201
WordPress Hooks 20
actionadmin_menuadmin\enhanced-welcome.php:20
actionadmin_initadmin\enhanced-welcome.php:21
actionadmin_enqueue_scriptsadmin\enhanced-welcome.php:22
actionplugins_loadedenhanced-blocks.php:44
actioninitenhanced-blocks.php:52
actionwp_headsrc\front-end-css.php:22
actionwp_headsrc\front-end-css.php:23
actionenqueue_block_assetssrc\init.php:67
actionenqueue_block_editor_assetssrc\init.php:106
actionwp_enqueue_scriptssrc\init.php:169
actionadmin_enqueue_scriptssrc\init.php:178
filterblock_categoriessrc\init.php:204
actionafter_setup_themesrc\init.php:222
filteradmin_body_classsrc\init.php:229
filterbody_classsrc\init.php:237
actionwp_footersrc\post-grid.php:17
actioninitsrc\post-grid.php:793
actionrest_api_initsrc\post-grid.php:826
actionafter_setup_themesrc\post-grid.php:882
actioninitsrc\social-share.php:188
Maintenance & Trust

Enhanced Blocks – Page Builder Blocks for Gutenberg Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 23, 2019
PHP min version
Downloads7K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Enhanced Blocks – Page Builder Blocks for Gutenberg Developer Profile

Mahmudul Hasan Arif

7 plugins · 40K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Enhanced Blocks – Page Builder Blocks for Gutenberg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/enhanced-blocks/build/index.css/wp-content/plugins/enhanced-blocks/build/index.js/wp-content/plugins/enhanced-blocks/admin/css/enhanced-welcome.css/wp-content/plugins/enhanced-blocks/admin/js/enhanced-welcome.js
Script Paths
/wp-content/plugins/enhanced-blocks/build/index.js/wp-content/plugins/enhanced-blocks/admin/js/enhanced-welcome.js
Version Parameters
enhanced-blocks/build/index.css?ver=enhanced-blocks/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
enhanced-welcome-containerenhanced-welcome-tabenhanced-panel-containnav-tab-activenav-tab-linkenhanced-wrapperenhanced-welcome-headerenhanced-section+10 more
HTML Comments
<!-- dashboard page --><!-- Features --><!-- <iframe class="enhanced-embed-responsive-item"
Data Attributes
data-tab-id="en-dashboard"data-tab-id="en-help"data-tab-id="en-review"
JS Globals
window.enhanced_blocks_admin_array
FAQ

Frequently Asked Questions about Enhanced Blocks – Page Builder Blocks for Gutenberg